{"id":"GHSA-pj2h-85jq-g5vg","summary":"Answer Missing Authentication for Critical Function","details":"Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.","aliases":["CVE-2023-4815","GO-2023-2051"],"modified":"2024-08-21T14:56:45.042469Z","published":"2023-09-07T09:30:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-09-08T12:20:46Z","nvd_published_at":"2023-09-07T07:15:08Z","cwe_ids":["CWE-306"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4815"},{"type":"WEB","url":"https://github.com/answerdev/answer/commit/e75142a55546e01d8904f59db228422561f51666"},{"type":"PACKAGE","url":"https://github.com/answerdev/answer"},{"type":"WEB","url":"https://huntr.dev/bounties/4cd3eeb4-57c9-4af2-ad19-2166c9e0fd2c"}],"affected":[{"package":{"name":"github.com/answerdev/answer","ecosystem":"Go","purl":"pkg:golang/github.com/answerdev/answer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-pj2h-85jq-g5vg/GHSA-pj2h-85jq-g5vg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"}]}